What Is a Security Risk & Threat Assessment?
A resilient security posture relies on evaluating two distinct but interconnected elements: threat and risk. While the terms are frequently conflated, evaluating one without the other leads to either misallocated capital or unmitigated exposure.
Together, they give you a clear picture of your exposure and the basis for decisions about where your security investment should go.
Threat Assessments
Adversary & Intent
Threat assessments evaluate potential adversaries and hostile environments, identifying who might target your personnel, physical assets, or organisation. We profile adversary motivation, operational capabilities, and intent, ranging from fixated individuals and organised crime to corporate espionage, hostile activists, and insider threats.
Risk Assessments
Probability & Impact
Risk assessments analyse how identified threats intersect with your physical, procedural, and personnel vulnerabilities. This process evaluates the probability of an exploitation occurring against the potential physical, financial, legal and reputational impact.
Our Risk & Threat Assessment Methodology
Every assessment follows the same analytical framework: four elements that, taken together, produce a complete and accurate picture of your exposure.
01. Threat Profiling
We begin by establishing who might target your assets, family, or organisation, and why. Utilising open-source intelligence (OSINT), regional threat monitoring, and adversary profiling, we evaluate:
- Hostile actor intent, motivation, and operational capabilities
- Fixated individuals, stalkers, and activist groups
- Organised criminal networks, corporate espionage, and insider threats
- Geographic, political, and regional baseline risk factors
02. Vulnerability Identification
We evaluate your existing physical, procedural, and personnel security controls to identify gaps an adversary could exploit. This involves reviewing:
- Estate perimeters and access controls
- Executive movements and travel patterns
- Domestic, corporate, and contractor staffing exposure
- Operational and information security (OPSEC) gaps
- Daily routines that create predictable patterns.
03. Likelihood & Impact Analysis
We weigh identified threats directly against your vulnerabilities using a standard risk matrix. Each scenario is scored on two key metrics:
- Probability (Likelihood): The realistic chance of an adversary exploiting a specific weakness, based on threat actor capability and historical intelligence.
- Impact (Consequence): The operational, financial, physical, legal, and reputational damage if an incident occurs.
04. Risk Prioritisation
Findings are mapped by risk level, distinguishing between what requires immediate action and budget, what should be monitored, and what can be accepted.
Instead of an unorganised list of recommendations, you receive:
- A prioritised action plan categorising fixes by critical, high, medium, and low urgency
- Risk mitigation measures designed around your operational realities, budget and daily routines
Documentation that meets the governance standards of insurers, corporate boards, and family offices.
Specialised Risk & Threat Assessments
We conduct specialised risk and threat assessments for specific environments and scenarios where a broader assessment alone does not provide sufficient depth.
Digital Footprint Assessment
Yacht Security Assessment
Campus & School Security Assessment
Insider Threat Assessment
Kabul: Safeguarding 350+ International Personnel in an Active Conflict Zone
Pegasus Ops was brought in to design and build a complete security infrastructure for a high-threat site in Kabul, housing more than 350 international personnel, following a catastrophic attack on a nearby compound that exposed critical failures in its existing security framework.
Security Risk & Threat Assessment FAQ
When should I commission a security risk assessment?
Security risk assessments are most often triggered by specific operational shifts, elevated exposure, or governance requirements.
- Following a direct threat, stalking incident, or security breach
- Before acquiring a new property, estate, or international asset
- Prior to high-profile events, media exposure, or significant life changes
- When existing security arrangements feel inherited rather than designed
- When board, legal counsel, or insurers require a formal and defensible risk review
If any of these apply, an initial conversation with our team will clarify whether a full assessment is the right next step.
What is the difference between a security risk assessment and a security audit?
A security audit evaluates existing security measures and whether it meets a standard. It does not tell you who might exploit the gaps it finds, or how likely they are to do so.
A security risk and threat assessment identifies potential adversaries and their intent, evaluates your physical, procedural, and personnel vulnerabilities, assesses the probability of an incident occurring, and quantifies the likely impact. The result is a complete risk picture and a prioritised plan for addressing it.
Do you only deliver a report, or do you help fix the vulnerabilities you find?
Both. Every assessment concludes with a prioritised report and a confidential briefing with our principals.
For clients who require it, we move beyond advisory into implementation, working directly with your team to resolve identified vulnerabilities, update protocols, and secure your environment.
Will the assessment disrupt daily operations or draw unwanted attention?
No. We operate with complete discretion and a minimal visible presence.
The majority of our preliminary work, including open-source research and digital exposure mapping, is conducted entirely off-site.
When on-site evaluations are required, we coordinate directly with your leadership or family office to ensure daily routines continue without interruption or unwanted attention.
Who carries out the assessment?
All engagements are led directly by our senior principals. We do not delegate risk analysis, physical site evaluations, or client briefings to junior staff or third-party contractors.
You maintain direct, confidential access to experienced operators throughout the entire process.
How long does a security risk and threat assessment take?
It depends on the scope and complexity of the engagement. A focused assessment covering a single residence, executive, or specific threat typically takes one to two weeks. Broader engagements covering multiple sites, international locations, or complex threat environments take longer and are scoped individually.
Timelines are agreed upfront and we work around your schedule and requirements.
Do you conduct assessments outside of London and the UK?
Yes. Headquartered in London, we conduct assessments across the UK, Europe, the Middle East, and Africa, as well as international waters for maritime engagements.
This includes residential estates, corporate sites, superyachts, and high-risk travel itineraries. International engagements are scoped individually based on the environment and threat context.
Do you offer ongoing support or is each engagement project-based?
We offer both. Many clients begin with a security risk and threat assessment, then transition to an ongoing advisory retainer. This provides continuous threat monitoring, regular protocol updates, and on-demand support during periods of heightened risk, travel, or significant life changes.